INSIGHTS
Universal 2nd Factor is an alternative to two-factor authentication. U2F was developed owing to the vulnerabilities of current two-factor authentication such as one time password (OTP) sent via SMS and the use of smartphones.
FIDO2 is an "open authentication standard, hosted by the FIDO Alliance, that consists of the W3C Web Authentication specification (WebAuthn API), and the Client to Authentication Protocol (CTAP)."
Another method organizations such as banks use in enhancing their authentication protocols is to send push notification to the user's mobile device, which the user has to click on before the transaction can be authorized.
Four authentication
technologies organizations and individuals may use to enhance their authentication processes or security
include Universal 2nd Factor standard, FIDO2
passwordless authentication, and
geolocation identification, and push notification. Below is a deep dive into each of these technologies/standards.
THE RISE OF UNIVERSAL 2ND FACTOR (U2F)
Universal 2nd Factor is an
alternative to two-factor authentication. U2F was developed owing to the vulnerabilities of current two-factor authentication such as one-time password (OTP) sent via SMS and the use of smartphones. When OTP is sent via SMS "
crooks can break it by using social engineering or compromising the user's phone." Other factors, such as the cost of sending out SMS for companies that have billions of users or cost of implementing "
expensive or complex solutions, such as providing every user with a unique token or smart card for its service."
 |
| FIDO U2F Security Key |
The U2F open authentication standard
was started by Google and Yubico, which allows users to use one token for authenticating to many services. Users are required to use a key/hardware token device like Yubico Key
on a web browser
that supports the U2F standard, such as Chrome and Firefox. "
The key device functions as a security token that lets the user login to multiple online services that support U2F, including custom-made applications."
Yubico describes the U2F standard as "
a challenge-response protocol extended with phishing and MitM [man-in-the-middle attack] protection, application-specific keys, device cloning detection and device attestation." The standard
uses asymmetric cryptography, also known as public-key cryptography. While U2F by itself is mostly safe, hackers can take
advantages in browser vulnerabilities "
to sidestep even Yubico's last bastion of login protection." For example, Google Chrome launched the
WebUSB, which
allows websites directly connect to USB devices. However, this new feature is a potential gateway for
phishers to
compromise a person's account by circumventing the checks that confirm that websites are the ones they claimed to be. In essence, U2F is dependent on other third parties keeping their side of the bargain, including how well
platforms like Google, Mozilla, and others apply the protocol in their browsers.
FIDO2 PASSWORDLESS AUTHENTICATION
FIDO2 is an "open authentication standard, hosted by the FIDO Alliance, that consists of the W3C Web Authentication specification (WebAuthn API), and the Client to Authentication Protocol (CTAP)." CTAP allows browsers to communicate with external authenticators. FIDO2 is an extension of the U2F described above. There are three possibilities with FIDO2, including:
Passwordless authentication, which utilizes a single factor authentication using a hardware authenticator that "eliminates the need for weak password-based authentication."
Two-factor authentication, which involves using a hardware authenticator in addition to a traditional password.
Multi-factor authentication involves "using a hardware authenticator and a PIN or biometric, to meet high assurance requirements such as needed for financial transactions and ordering a prescription."
GEOLOCATION IDENTIFICATION AND PUSH NOTIFICATION
Another way organizations confirm the user is the one making the said transaction is through geolocation identification, which is made possible through the user's mobile device. For example, a bank can access a customer's location to confirm they are in the same physical location in which the transaction was requested. Another method is to send push notifications to the users' mobile device which the user has to click on before the transaction can be authorized.
Conversation
Leave a comment through Blogger →